Psyber Security Training
There’s a great article on our main website Blog page by our MD Sarah. I’ve copied it here too:

Psyber Security
The Need to Remember the Role of Behavioural Science in Security Process Development
Human behaviour is a key element of security process design. It is key to ensuring that the policies and procedures that are developed to protect an organisation’s critical information are followed and adhered to. Attackers (hackers, scammers, fraudulent actors, pentesters and con artists) all focus on exploiting not just the technical aspects of an organisation, but also exploiting the cognitive vulnerabilities of an organisation’s workforce, through deception and social manipulation. Professional ‘Human Hackers’ or more accurately Social Engineering professionals, such as Jenny Radcliffe have been explaining this exploit for some time.
When an organisation does suffer an attack to their critical information (whether successfully battled or not) the internal investigation almost always uncovers a human factor or element involved in the attempt by the attacker. Attacks often rely on simple acts of deception and social manipulation rather than solely on cutting-edge technology.
Attacks that are very persistent and consistently targeting the same organisation are dramatically increasing for many of our Commercial, Government and Military-linked clients. These persistent attacks focus on incessantly targeting a specific company or organisation in order to exploit, make public critical information, gain financial advantage, sabotage products, services or organisational messages and reputations.
Many of these attacks may rely on a single individual unwittingly opening a ‘contaminated’ link or a document that then delivers customised malware, which in turn infects the organisation’s computer network. Once the compromise has loaded the attackers can then attempt to access the organisation’s critical information.
Security practitioners with a background in psychology are assisting organisations to develop ‘actionable’ human strategies and processes that merge and complement traditional cyber and physical approaches to securing (and maintaining the security of) an organisation’s critical information. A background in psychology enables the knowledge of; deception studies, human factors in design, decision strategy development, change management, leadership, bystander intervention, neuro-linguistic processing, authority studies and cognitive processes to be applied to the development of usable, real world, practical defence strategies.
Attackers Use Social Engineering
Attackers, focussed on the exploitation of an organisation’s critical information for whatever their motivational reasons (political, financial, etc) have developed adaptive and versatile techniques to counter the counter measures and processes that are implemented by a target organisation to prevent the attackers success. These counter measures and critical information defence strategies must be versatile and adaptive also. When an individual is faced with a situation where they are required to make a decision, (whatever that decision is; whether to click a link, open an attachment, hold a door for someone, forward a message, answer a request for seemingly unimportant information, etc) they rely on their past experiences, memories and knowledge. They make comparisons with previous similar situations, they draw on the knowledge and information they have.
Psychological Knowledge
Psychologists study and explain key human behavioural concepts like social proof, commitment, and reciprocity and therefore can realise the importance of real world example awareness training to solidify and ‘make real’ critical information attacks. Hearing about, understanding the consequences and knowing the opportunities to thwart a successful critical information attack cements the knowledge base of an employee and assists them to make the correct decisions when faced with attack methodology.
Psychologists and computer security engineers have, through experimental research, discovered that cybersecurity generally has low observability. For example one employee has no overt knowledge of how secure another employee’s password choice is or what security settings they may have in place regarding their own personal data. They have also found that social proof can positively influence’s an individual’s awareness, knowledge and motivation to be more secure. Think of how if you hear of a person losing all of their personal photos that they have stored on their phone, will then prompt many of you to back up your device as they ‘don’t want it to happen to me!’ Hearing that a spate of ‘hook and cane’ burglaries were taking car keys from inside homes when those keys were placed close to the door, prompted people to change their behaviour and place their keys in a different place within their home. The key to these decisions, actions or behaviour changes are real life examples and consequences.
An acceptance that every employee is vulnerable to being exploited by attackers intent on accessing an organisation’s critical information is essential to assist in the development of effective organisational security policies and processes. There are some employees that, due to their own personality traits or experiences, may be more susceptible to manipulation from attackers. Organisations can, through real-life example awareness training, train their employee’s to make the correct decision or take the right action that results in defending the organisation’s critical information.
Verrimus offer cost-effective, critical information defence training. For further details of our TSCM courses click here.
Sarah L.H. Saul
BSc (Hons) Applied Psychology